Security by design practices for IT projects management in SMEs

Autor: Javier Saenz-Marcilla, Magdalena Arcilla-Cobián, Jose A. Calvo-Manzano, Mercedes de la Cámara
Rok vydání: 2016
Předmět:
Zdroj: 2016 11th Iberian Conference on Information Systems and Technologies (CISTI).
DOI: 10.1109/cisti.2016.7521485
Popis: Secure by Design (SBD) is oriented to secure software development project management. This article presents the results of a research where SbD practices are mapped to the practices, activities and control objectives proposed by the major frameworks and standards that deal with the management of software development projects. These frameworks are divided into three organizational levels (strategic, tactical and operational). The results of the research show the main contributions and lacks of these frameworks into managing projects for the development of secure software product. Furthermore, in the environment of SMEs, this study makes it easier for IT professionals implementing practices, activities, and security control objectives, integrating different frameworks and standards of governance and management in IT development projects.
Databáze: OpenAIRE